#cisa-kev
10 articles
Government and technology organisations across global regions, including North America, the United States, and the EU, were the primary focus of the 10 articles tagged cisa-kev from April to August 2026. Coverage centred on critical and high-severity vulnerabilities, with CVE-2026-48907, CVE-2023-49105, CVE-2026-65400, CVE-2026-42271, and CVE-2026-18556 drawing particular attention across enterprise and media sectors. The reporting reflected a severity mix of four critical, four high, and two medium issues, with enterprise software frequently cited as an affected area.
CRITICALCVE-2023-49105: ownCloud Flaw Exploited to Steal Nuclear Research Data
CVE-2023-49105 (CVSS 9.8) added to CISA KEV after Chinese-speaking actor exploited it to steal nuclear research records from a Philippine agency. Patch now.
CRITICALCVE-2026-65400 macOS Flaw Added to CISA KEV, Actively Exploited
CISA added CVE-2026-65400, a 9.8-CVSS macOS authentication bypass, to its KEV catalog on August 18, confirming active exploitation. No patch yet.
HIGHCISA Adds Exploited N-able N-central Flaw to KEV Catalog
CISA adds CVE-2026-18577 (CVSS 8.2) to KEV after active exploitation; incomplete patch for CVE-2026-18556 in N-able N-central. Patch now.
CRITICALCISA Adds Joomla JCE Flaw CVE-2026-48907 to KEV Catalog
CISA warns of active exploitation of CVE-2026-48907, a CVSS 10.0 improper access control flaw in Widget Factory Joomla Content Editor (JCE) allowing unauthenticated PHP code...
HIGHCVE-2026-42271: LiteLLM Flaw Exploited in the Wild, CISA Adds to KEV
CISA added CVE-2026-42271 (CVSS 8.7) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against BerriAI LiteLLM deployments.
MEDIUMCVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEV
CISA added CVE-2026-9082 (CVSS 6.5) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against all supported Drupal Core versions.
HIGHCVE-2024-57728: SimpleHelp Path Traversal Lets Admins Upload
CISA adds CVE-2024-57728 to Known Exploited Vulnerabilities: SimpleHelp path traversal via zip slip allows admin users to upload arbitrary files and execute code. Due May 8, 2026.
HIGHCVE-2025-2749: Kentico Xperience Path Traversal Under Active Exploit
CISA adds CVE-2025-2749 to KEV catalog: Kentico Xperience path traversal lets authenticated Staging Sync Server upload arbitrary files. Due date for federal agencies: May 4, 2026.
MEDIUMNIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEs
NIST now enriches only 15-20% of CVEs under new policy as of April 2026, leaving 80% without CVSS scores or product mappings.
CRITICALMicrosoft Office Excel Flaw Exploited in Active Attacks
CISA orders federal agencies to patch CVE-2009-0238, a 17-year-old Microsoft Office Excel remote code execution flaw, by April 28, 2026, due to active exploitation.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.